gjc-sdk-operate

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to interact with the gjc CLI. It includes defensive programming requirements, such as mandating that all data be passed as argv values rather than via shell command strings, which prevents shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges and manages the risks associated with processing external tool outputs.
  • Ingestion points: Data enters the agent's context through the output of gjc CLI commands (e.g., session list, raw query).
  • Boundary markers: A mandatory, single-use human approval workflow is required before any command is executed, acting as a critical safety boundary.
  • Capability inventory: The skill facilitates specific session management and control operations via the gjc CLI, as documented in the allowlist.
  • Sanitization: The instructions require the use of structured JSON for machine communication and mandate SHA256 integrity checks when retrieving error evidence fragments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 04:42 PM
Security Audit — agent-trust-hub — gjc-sdk-operate